Earlier quoted context omitted.
Not just phishing - you could lose your password via malware, or if services store passwords in clear text and get hacked.
I use different passwords for every service. Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected. If the service is hacked, the hacker probably has direct access to everything the password was protecting.
Any well-secured service should protect critical actions with 2fa. “oh, are you sure you want to transfer all your funds? Please re-authenticate first”